Impact
The vulnerability is an assertion failure in MongoDB Server that can be triggered by an authenticated user with write privileges by sending crafted retryable write commands. This causes a fatal crash that is persisted, making the server repeatedly crash on restart. The result is a denial of service that can spread to other nodes in a sharded cluster.
Affected Systems
MongoDB Server is affected. Version details were not specified in the advisory, so all deployments running MongoDB Server that support retryable writes are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high impact. Because the attack requires authenticated write access, the attack vector is internal. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation. However, the persistent crash can be destructive, so the risk remains significant if credentials are compromised.
OpenCVE Enrichment